📣

Advertisement

Google Ad - 970×90 Leaderboard  TOP_LEADERBOARD_4

The Ransomware Pivot to Critical Infrastructure
Article

The Ransomware Pivot to Critical Infrastructure

Recent breaches at McKesson, Novocure, Berlin, and a freelancer malware campaign reveal a coordinated attack on healthcare and municipal systems, demanding a strategic U.S. response.

Arjun NairSeptember 2, 20266 min read

Photo: TechCrunch

📣

Advertisement

Google Ad - 970×90 Leaderboard  TOP_LEADERBOARD_4

The Thread

The four stories that broke across the cybersecurity desk in the last 48 hours share a single, sobering thread: attackers are no longer content with stealing credit cards or encrypting small businesses. They are deliberately hitting organizations that hold life-critical data and provide essential public services - healthcare giants, cancer patients, city administrations - and they are doing so with a combination of extortion, espionage, and outright sabotage. The pattern is not random. It reflects a strategic pivot toward targets whose disruption causes immediate human harm and whose leaders feel the greatest pressure to pay.

For U.S. technology companies and consumers, this means the threat model has shifted. It is no longer enough to protect payment data or intellectual property. The new front line is the infrastructure that keeps people alive and cities functioning. The response cannot be purely technical; it must also be regulatory, organizational, and diplomatic.

The Healthcare Magnet

Two of the four logged stories involve U.S. healthcare entities. As TechCrunch reported, McKesson - the company that distributes medicines and medical devices to hospitals and practices across the country - was hacked, with attackers claiming millions of patient records stolen. The company said it expects intermittent service degradation. In other words, a compromise of a linchpin distributor can ripple out to every clinic and pharmacy that depends on it. Novocure, a healthtech company, reported that more than 1,400 U.S. cancer patients had their data exposed in a mid-August cyberattack, according to BleepingComputer. That is not a number that will move markets, but it is a number that represents vulnerable individuals whose medical histories are now in criminal hands.

Why healthcare? Because the data is sensitive enough to hold for ransom, and the operational dependence is extreme. Hospitals cannot stop treating patients while they rebuild a server. A distributor like McKesson cannot simply turn off its systems and wait. The attackers know that the cost of downtime is measured in lives, not just dollars. That gives them leverage that a bank or a retailer does not offer.

The Municipal Angle

Berlin’s city administration confirmed that it suffered a data theft after the Rhysida ransomware gang listed it on their leak site, as BleepingComputer reported. Although Berlin is not a U.S. entity, the pattern is directly relevant to American municipalities. U.S. cities have been frequent targets of ransomware for years, from Atlanta to Baltimore to smaller county seats. The Berlin case adds a new twist: the attackers are not just encrypting files; they are threatening to publish stolen data. That turns a technical nuisance into a public relations and privacy disaster, and it increases the likelihood that a city will pay to suppress the leaks.

For U.S. technology companies, the municipal market is a major customer segment. When a city is hit, it often turns to outside vendors for incident response, forensics, and recovery. But more importantly, the pattern suggests that attackers are now targeting government entities as a gateway to citizens’ data. If Berlin’s data was stolen, it likely includes personal records of residents. U.S. cities hold similar troves - tax records, utility bills, police reports, and more. That makes them attractive targets, and the public sector’s historically weak security posture compounds the risk.

The Freelancer Vector

The third story - the indictment of a Russian national for infecting 80,000 freelancers with malware - ties the other threads together. As BleepingComputer reported, the phishing campaign used TVRAT and DarkVNC malware. Freelancers may seem like an odd target, but they are a logical one. They often work from personal devices, lack enterprise security, and handle sensitive data for multiple clients. An attacker who compromises a freelancer can access the systems of every company that freelancer serves. That includes healthcare vendors, city contractors, and technology firms.

Advertisement

📣

728x90

MID_CONTENT_2

The fact that a U.S. federal grand jury indicted the perpetrator shows that law enforcement is watching, but the scale - 80,000 victims - illustrates how ineffective deterrence has been. The attacker was allegedly Russian, which adds a geopolitical dimension. For U.S. companies, this is a reminder that their supply chain includes not just other corporations but a vast army of independent contractors who may be the weakest link. The typical response - training and endpoint protection - is not enough when the attacker is targeting the human factor at scale.

A Coordinated Playbook

What unites these stories is not coincidence but a playbook. The attackers use phishing to gain a foothold, deploy remote access trojans to move laterally, then exfiltrate data and deploy ransomware for maximum leverage. They choose targets where the data is sensitive and the operational continuity is critical. They operate from jurisdictions where extradition is unlikely. And they are indiscriminate - hitting a multinational corporation, a cancer-care equipment maker, a city government, and individual freelancers all in the same week.

For U.S. technology companies, the implications are direct. First, they must assume that every partner, vendor, and contractor is a potential entry point. Second, they must recognize that the value of their data is not just financial but also existential - if it includes patient records, it can be used to extort not only the company but the patients themselves. Third, they must plan for the possibility that an attack will cause service degradation, as McKesson said, and that such degradation can have cascading effects on public health and safety.

The U.S. Response Gap

None of this is hypothetical. The Federal Bureau of Investigation and the Cybersecurity and Infrastructure Security Agency have long warned about these threats, but the private sector has been slow to adopt mandatory security standards. The healthcare sector, in particular, has been exempt from many disclosure requirements or has faced penalties that are too low to change behavior. The result is a market failure: companies underinvest in security because the cost of a breach is often lower than the cost of prevention. But when the breach involves millions of patient records or a city’s data, the external costs - to patients, residents, and public trust - are enormous.

The U.S. government has taken some steps, such as indictments and sanctions, but as the Berlin case shows, foreign attackers are undeterred. The U.S. Congress has debated a federal data breach notification law for years without passing one. Meanwhile, the attack surface keeps growing, as evidenced by the Novocure breach, which occurred in mid-August and was only now disclosed, a delay that is all too common.

What to Watch

Going forward, the most important signal will be whether U.S. authorities begin to treat these attacks as a national security matter, not just a criminal one. The McKesson breach, if the hackers’ claim is true, could become one of the largest healthcare data breaches in U.S. history, and the fallout will be watched closely by every hospital and insurance company. The Novocure case will set a precedent for how much detail companies are required to give about patient impact. The Berlin response will show whether municipal governments can withstand extortion attempts without paying. And the freelancer indictment will test whether international cooperation can disrupt these campaigns before they expand.

For U.S. consumers, the takeaway is stark: their trust in the institutions that handle their most personal information - their health, their identity, their city services - is now a tactical weakness. Until companies and governments act on the assumption that they are already inside the perimeter, and design defensive strategies accordingly, the pattern seen this week will repeat, with ever more consequential targets.

More on this beat: Cybersecurity on TechManNews.

Advertisement

📣

728x90

IN_ARTICLE_5

#data breach#hackers#hacked#breach#devices#data

Newsletter

Get Tech News in Your Inbox

The latest AI, gadgets, software and startup stories from TechManNews, delivered every morning - free.